Official intent
Make vendor and remote access to OT brokered, logged, and time-bound — never standing or direct. The official source remains authoritative.
Read the official campaign ↗Why it matters
Standing remote access is a permanent, often forgotten door with the vendor's password on it. Compromise of a vendor or a shared credential then lands directly in production. Brokering, time-bounding, and logging access shrinks that exposure to a supervised window and gives you a record of who did what.
Tightening remote access can cut off a vendor mid-support or during an emergency. Coordinate with operations and vendors before changing pathways, keep a tested emergency-access procedure, and stage changes so support is never silently severed when the plant needs it.
Minimum / Strong / Advanced
All remote and vendor access paths are inventoried; direct, always-on tunnels into OT are removed or brokered.
Access goes through a jump host in a DMZ with strong authentication, is enabled per session/window, and is logged.
Sessions are supervised or recorded, access is least-privilege and just-in-time, and vendor accounts are provisioned and revoked per engagement.
Implementation timeline
- Inventory every remote and vendor access path into OT
- Disable any unknown or always-on tunnel
- Route remote access through a controlled jump host / DMZ
- Require strong authentication (MFA) for all remote entry
- Make access time-bound — enabled per session or window
- Log all remote sessions and their actions
- Add supervision or recording for vendor sessions
- Provision and revoke vendor access per engagement
Implementation steps
- Inventory all remote and vendor access into OT, including modems and forgotten tunnels.
- Force remote access through a brokered jump host in an IT/OT DMZ — never directly to a device.
- Require strong authentication and least privilege for every remote connection.
- Enable access only for the session or window it is needed, then disable it.
- Log — and where possible supervise or record — remote sessions, and revoke vendor access after each engagement.
Validation
- Attempt to reach an OT device remotely without going through the jump host — it must fail.
- Confirm no always-on vendor tunnel remains enabled between support visits.
- Verify remote sessions are logged and vendor access was revoked after the last engagement.
Evidence to retain
Remote/vendor access policy with time-bound and emergency procedures
Jump-host/DMZ design and remote-access account settings
Remote session logs and per-engagement provisioning records
Test showing direct remote access is blocked; access-revocation records
Common failure modes
An always-on vendor VPN nobody remembers, a shared vendor login used across sites, and remote access that is logged but never reviewed. Access that is convenient for the vendor at all times is convenient for an attacker at all times.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.